Cutwail

First seen
2007-12-01 00:00:00
Malware type
botnet, ddos
Family
Malware family
Last IoC activity
2026-07-12 06:29:16
Profile updated
2026-07-07 12:40:38

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Context

Cutwail is a notorious botnet primarily used for sending spam emails and conducting DDoS attacks. It has been one of the largest and longest-running spam botnets, often utilized in combination with other malware to distribute malicious payloads.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Cutwail_Auto (yara-rule)

Related threat objects

  • Cutwail (infrastructure)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • secureworks.com — Gold Essex (report)
  • CrowdStrike — Report2021Gtr (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
  • shadowserver.org — Has The Sun Set On The Necurs Botnet (report)
  • web.archive.org — Blackhat Eu 2010 Carrera Silberman State Of Malware Slides (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cutwail (report)
  • secureworks.com — Gold Essex (report)
  • McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
  • mimecast.com — How To Slam A Door On The Cutwail Botnet Enforce Dmarc (report)
  • github.com — 2020 09 07 Dridex Iocs.Txt (report)
  • McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
  • securityintelligence.com — Dridex Campaign Propelled By Cutwail Botnet And Powershell (report)
  • darknetdiaries.com — 110 (report)
  • jsac.jpcert.or.jp — Jsac2020 5 Sajo Takeda Niwa En (report)

External references